Data Sovereignty Routing in Distributed Services Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current distributed network architectures and cloud-based deployments of computing services face significant challenges in implementing and enforcing data sovereignty regulations, particularly due to the geographic distribution of enterprise installations and service provider nodes across different regions with varying regulatory requirements.

Innovation Solution

A distributed services network architecture is implemented with multiple nodes, each providing independently accessible interfaces for services like fax, email, and SMS. Each node maintains user accounts with region identifiers and a data sovereignty configuration, which directs users to nodes that are data sovereign for their region, ensuring compliance with relevant regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed network architectures and cloud-based deployments are used, then service accessibility and flexibility are improved, but data sovereignty compliance becomes extremely difficult

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata sovereignty compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the distributed network into multiple geographic regions, each with its own nodes that independently handle data sovereignty compliance for their respective regions. This segmentation allows the system to maintain service accessibility across the distributed network while ensuring that data remains compliant with local regulations by processing it within the appropriate regional boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a data sovereignty determination service as an intermediary component that mediates between user requests and service nodes. This intermediary determines the appropriate service node based on data sovereignty requirements and directs requests accordingly, enabling the distributed architecture to maintain compliance without requiring users to manually manage regional constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If computing services are distributed across multiple geographic regions, then service redundancy and availability are improved, but the complexity of managing data sovereignty regulations increases

Engineering Contradiction:
Improveservice availabilityVSAvoidregulation management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically determining data sovereignty requirements and directing user requests to appropriate service nodes without requiring manual intervention. The data sovereignty determination service autonomously evaluates regulations and routes requests, reducing the operational complexity of managing distributed services across multiple geographic regions while maintaining service availability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If users can access services from any node, then service flexibility is improved, but control over data location and sovereignty compliance deteriorates

Engineering Contradiction:
Improveservice access flexibilityVSAvoiddata location control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the data sovereignty determination service receives user requests, determines the appropriate service node based on data sovereignty requirements, and redirects requests accordingly. This feedback loop maintains service flexibility for users while ensuring data location control and compliance by automatically adjusting request routing based on regulatory requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12287896B2System and method for implementing data sovereignty safeguards in a distributed services network architecture
Publication Date: 2025.04.29 OPEN TEXT CORPORATION
  • US12287896B2 patent drawing
  • US12287896B2 patent drawing
  • US12287896B2 patent drawing

AI summary

Embodiments of systems and methods for implementing data sovereignty safeguards in a distributed services network architecture are disclosed. Embodiments of a distributed services system may have a number of distributed nodes that each implements a set of services. When a user requests a service at a particular node of a distributed services system, the node is configured to determine if that node is not (or is) data sovereign for a region associated with the user. If the node is not data sovereign for the user's region, the user may be directed to a corresponding service at a node of the distributed service system that is data sovereign for the user's region.